Description
Certain versions of the WordPress theme OptimizePress contain a file that can be used by attackers to upload arbitrary files on the web server and execute the code contained in these files. The vulnerable file is wp-content/themes/OptimizePress/lib/admin/media-upload.php.
Remediation
Delete wp-content/themes/OptimizePress/lib/admin/media-upload.php file.
References
Related Vulnerabilities
ThinkPHP v5.0.22/5.1.29 Remote Code Execution Vulnerability
Horde Imp Unauthenticated Remote Command Execution
Squid Improper Input Validation Vulnerability (CVE-2016-2390)
WordPress Plugin Similar Posts-Best Related Posts for WordPress Remote Code Execution (3.1.5)
WordPress Plugin WordPress Comments Import & Export CSV Injection (2.0.4)